a CLOUDFLARE SOLUTION BRIEF 


Complimentary Phishing Risk Assessment 


Cloudflare Area 1 identifies and blocks the threats bypassing your current email defenses 


Cloudflare Area 1 is designed to protect organizations from the 
cause of over 90% of data breaches: phishing attacks. In Q2 2022 
alone, the Anti-Phishing Working Group observed over 1 million total 
phishing attacks, representing “the worst quarter for phishing that 
APWG has ever observed.” 


As part of the Cloudflare Zero Trust platform, Area 1 email security 
inherently assumes that no email can be trusted. We preemptively 
identify phishing campaigns, attacker infrastructure, and attack 

delivery mechanisms during the earliest stages of an attack cycle. 


Discover and stop the threats that are currently evading your email 
defenses with a complimentary phishing risk assessment. 


e e. 
ŠETA. Area 1 frequently catches 30% more phish than 
ae ees EOR legacy secure email gateways (SEGs) and cloud 
99.96% UPTIME (view more) email suites. 
[\ ja L 
V \ i unk 27% With an Area 1 phishing risk assessment, you'll 
1775 5 95) — | DT ARR i access customized, real-time data on: 
p | IDENTITY DECEPTION | 15% 
? E erano mPeRsonaTon | 9% 
UPDATES EVERY 15 MINS . . . . . 
So moms e Who within your organization is most targeted 
GEES aia by phishing 
l — “— e What specific threats are evading your other 
‘ela Aan a defenses (e.g., SEGs, cloud email suite, email 
beth.huffman@mycompany.com | 1,540 pepe a . . 
arene = ian authentication protocols) 
EOE ao eal e Which attack groups and Indicators of 
maegan.sanders@mycompany.com | 230h an l = @ SPAM | 320 3% CB 7 . 
EEA E a mics a Œ Compromise you are facing 
UPDATES EVERY 15 MINS [vewau ] k & & p & & . o soe . 
+ pe mere e Where the malicious attacks are originating 


| UPDATES EVERY 15 MINS VIEW ALL 


e How to close any current email security gaps 
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Cloudflare Area 1 Phishing Risk Assessment 


How it Works 


The best way to assess the effectiveness 
of security products is by using real-world 
data. Area 1’s fully elastic, cloud-native 
service lets you get up and running in 
minutes, without needing to deploy any 
hardware or software. 


e Setup in minutes without affecting mail 
flow or impacting your end users. 


e Choose the deployment option best for 
your organization — inline, API or multi- 
mode. 


e Integrate Area 1 into your SIEM and other 
security integration points to get full 
detection metrics and forensic details. 


e Our assessment typically runs for 15 to 
30 days, after which we will deliver an 
in-depth custom analysis. You can access 
your dashboard at any time during the 
assessment. 


e Your Area 1 account team will also alert 
you in real-time to critical phishing 
incidents during the assessment. 


Sample phish missed by existing 
controls 


This is an example of a supply chain 
email attack, where the business 
partner's email account was likely 
compromised first. The compromised 
account was then used to phish 
another organization. This phishing 
email was missed by Proofpoint, but 
detected by Area 1. 
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Area 1 will process forwarded messages from your SEG or email provider 
via BCC or journaling rules, to identify and block any missed threats. 
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You have a new FedEx noke Lele Business Partner 


You have a new FedEx notification Open Now https://bit[.]ly/203WZEr 


> https://yesmaturetube[.]ru/zxcv/ 
FedEx 


Dear Customer. 


Your package has arrived on September 23rd. Due to the incorrect address the courier cannot ship your package to you. This is an automated email that requires 
immediate attention so we can complete the delivery of your package today. 


Help us complete today’s package delivery by reconfirming your address. Please select any of the preferred option below to receive your package. 
1) To receive your package please go to the nearest FedEx office and show this receipt Print Receipt. 

2) Click Here to update your address and phone number and check your shipping documents and invoice 

Greetings 


— es 
2019 © Fedex Courier International GmbH. all rights reserved. 
International Express Customer Service Hotline: 800.988.1888 
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Cloudflare Area 1 Phishing Risk Assessment 


Example assessments 


Cloudflare Area 1 hunts for phishing infrastructure, sources and delivery 
mechanisms, blocks campaigns across different attack vectors, and 
provides end-to-end phishing triage and response. We stop the most 
sophisticated and malicious phishing attacks that we often observe 
traditional SEGs missing. 


Below are examples of one-month observations from organizations using 
other email security providers. It takes just one missed threat to cause a 


security disaster. 


Missed threats in a one-month period sitting 


behind other email security providers. 


Organization Email security Missed Total email 
industry system used threats volume 
Insurance Microsoft 365 517,968 103,099,539 

Pharmaceutical Proofpoint 448,440 432,611,141 

Ci Email S it 
Food & Beverage agen cues capa 105,603 420,088,334 
(IronPort) 
Education Custom 90,763 142,672,221 
Financial Services Mimecast 1,727 17,223,584 


See for yourself how Cloudflare Area 1: 


v Prevents BEC and email-based fraud 


v Protects against low-volume and highly targeted attacks 


v Accelerates phishing triage and response 


Get started with a risk-free phishing risk assessment today. 
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